Explainer
    Concepts
    Concepts

    Part of The company brain: where your organization's knowledge lives

    What is the EU AI Act? What applies now and what applies from December 2027

    The AI Act regulates AI by risk. Which obligations already apply, what the Digital Omnibus postponed, and what your organisation needs to arrange now.

    Max van Genderen5 min read
    Share on
    What is the EU AI Act? What applies now and what applies from December 2027

    The EU AI Act (Regulation (EU) 2024/1689)1 is the European law that regulates AI by risk. The greater the impact of an AI application on people, the heavier the requirements. The law applies in phases. Some obligations are already in force, and the heaviest requirements for high-risk AI apply from 2 December 2027.

    There is a lot of noise around the AI Act. One day you read that the law is "off the table", the next that every chatbot becomes a compliance project. Neither is true. This article explains what the law covers, what already applies and what your organisation actually needs to do.

    The AI Act in one sentence

    The AI Act sorts AI applications into four risk levels and attaches its own rules to each level. Separate rules apply to the makers of large AI models.

    The four risk levels

    LevelExamplesWhat the law requires
    Unacceptable riskSocial scoring, emotion recognition in the workplace, manipulation of vulnerable groupsProhibited
    High riskAI in recruitment, employee assessment, credit scoring, education, critical infrastructureRisk management, data quality, logging, human oversight, documentation
    Limited riskChatbots, AI-generated text, images and audioTransparency: people must know they are dealing with AI
    Minimal riskSpam filters, stock or demand forecasting, most internal analyticsNo specific requirements beyond AI literacy

    Most AI in a typical organisation falls under limited or minimal risk. Think of asking questions of your own data, searching documents or flagging anomalies. That changes as soon as AI is used to assess people. Then you quickly end up in the high-risk category.

    04Unacceptable riskProhibited, such as social scoring03High riskAssessing people: hiring, HR, credit02Limited riskChatbots and AI content: make it recognisable01Minimal riskInventory, spam, internal analysisThe greater the impact on people, the heavier the requirements.

    What applies when

    The Digital Omnibus (Regulation (EU) 2026/1744)2 changed the timeline. That change has applied since 27 July 2026.

    DateWhat applies
    2 February 2025Prohibited AI practices and the AI literacy obligation
    2 August 2025Rules for providers of general-purpose AI models
    2 August 2026Transparency obligation: chatbots and AI content must be recognisable as AI
    2 December 2026Machine-readable marking for generative AI that was already running before August 2026; new bans on non-consensual intimate imagery and AI-generated child sexual abuse material
    2 December 2027High-risk AI under Annex III, such as recruitment, HR, credit and education
    2 August 2028High-risk AI embedded in regulated products (Annex I)

    Postponed is not cancelled. The delay only covers high-risk AI. The transparency obligation, the prohibitions and AI literacy all still apply.

    Feb 2025Prohibitions and AI literacyAug 2025Rules for general-purpose AIAug 2026Transparency obligationDec 2027High-risk AI (Annex III)Aug 2028High-risk in products (AnnexI)The AI Act applies in phases. Only high-risk has been postponed.

    Provider or deployer?

    The AI Act distinguishes between the party that builds an AI system (the provider) and the party that uses it (the deployer). Most organisations are deployers. They don't build a language model, but use one for their own work.

    That doesn't put you out of scope. As a deployer, you are responsible for, among other things:

    • transparency towards the people who deal with your AI;
    • AI literacy of employees who work with AI;
    • for high-risk AI: human oversight, keeping logs, using the system according to its instructions, and informing affected employees.

    Note: if you substantially modify an AI system or put it on the market under your own name, you may be treated as a provider yourself, with the heavier requirements that come with it.

    When does your AI become high risk?

    The question is not which technology you use, but what you use it for. The same language model can be minimal risk when it answers stock questions and high risk when it ranks job applicants.

    Signs you are moving towards high risk:

    • AI assesses, selects or ranks people;
    • AI monitors the behaviour or performance of employees;
    • AI helps decide whether someone gets access to credit, education or essential services;
    • AI controls critical infrastructure.

    A practical red line: never use communication data such as email and Teams to assess or monitor employees. It keeps you out of the heaviest category and protects the trust of your people.

    Fines and supervision

    The fines are substantial:

    • up to €35 million or 7% of global annual turnover for prohibited practices;
    • up to €15 million or 3% for most other violations.

    In the Netherlands, the national implementing act (Uitvoeringswet AI-verordening) is in draft. It gives the Dutch Authority for Digital Infrastructure (RDI) and the Dutch Data Protection Authority (AP) a coordinating role, with sector regulators below them. Other member states have their own national set-up.

    How the Netherlands organises supervision and which supervisor fits your organisation is covered in The AI Act in the Netherlands: which law applies and who supervises.

    The AI Act does not stand alone

    The AI Act overlaps with other legislation:

    • The GDPR continues to apply as soon as personal data enters AI. A data protection impact assessment (DPIA) is often already required for sensitive applications, regardless of the AI Act.
    • NIS2, implemented in the Netherlands as the Cybersecurity Act (Cyberbeveiligingswet), sets requirements for the security of the systems your AI runs on. What that asks of your data and AI layer is covered in NIS2 and the Dutch Cybersecurity Act: what your data and AI layer must be able to prove.

    How to make all three manageable together is covered in AI governance for boards and supervisory boards: value, ethics and stop rules.

    What to arrange now

    1. Create an AI register. Which AI is running, for what purpose, and who owns it? Don't forget Copilot licences and standalone tools.
    2. Classify each application by risk level, and record why. Repeat this when the use changes.
    3. Make AI recognisable. Since 2 August 2026, chatbots, AI answers and AI content must be recognisable as AI.
    4. Arrange AI literacy. Train employees and management in what AI can do, what it can't and where the risks are. That includes executives and supervisors. For the questions a supervisory board should ask about this every quarter, read Five questions every supervisory board should ask about AI each quarter. What that means per role is covered in AI literacy: what the AI Act asks of employees, management and supervisors.
    5. Draw a red line on assessing people, and record it in policy.
    6. Make sure you can prove what happens. Traceable answers, logging of questions and answers, and access managed per user. For high-risk AI it is mandatory, and in all other cases it is your best evidence.

    That last point is not a legal question but a data question. If you can't trace where an answer came from, you can't prove your AI does what you promise. See also Implementing AI: why it almost always fails on your data.

    Frequently asked questions

    Does the AI Act apply if we only use ChatGPT, Claude or Copilot? Yes. You are then a deployer. The transparency obligation and AI literacy apply, and the risk category depends on what you use it for.

    Has the AI Act been postponed? Only the requirements for high-risk AI, to 2 December 2027 and 2 August 2028. The prohibitions, the transparency obligation and AI literacy already apply.

    Does the AI Act apply to SMEs? Yes. There are lighter documentation requirements for smaller organisations, but the core obligations apply to everyone who uses AI.

    Who in the organisation is responsible? Using and classifying AI is an executive decision, not an IT judgement. Every application has one business owner.

    Where do you start? With the AI register. Without an overview of what is running, you can't classify anything. Request a foundation scan.

    Sources

    Every claim in this article can be checked at the source.

    1. 1
    2. 2
    3. 3
      AI-verordening

      Autoriteit Persoonsgegevens

      Back to the text

    Next step

    Want to see what's already inside your organization?

    Leave your details. We'll reach out and plan a scan. Within thirty days you'll see one concrete result.

    No newsletter, no reselling. Just this conversation.

    Comments

    Comments are reviewed by the editors before they appear.

    Use your Google or Apple account, or your business email address.

    Sign in to comment